An Android banking trojan named SharkBot has been disguised as an antivirus app on Google Play Store. SharkBot malware belongs to a category of financial trojans that could siphon credentials to initiate money transfers from compromised devices by circumventing multi-factor authentication mechanisms.
The malware was first spotted on the scene in November 2021 and is similar to its malware counterparts TeaBot, FluBot, and Oscorp (UBEL).
SharkBot has the ability to carry out the unauthorized transactions via Automatic Transfer Systems (ATS), which stands in contrast to TeaBot, which requires a live operator to interact with the infected devices to conduct the malicious activities.
The ATS features allow the malware to receive a list of events to be simulated, and they will be simulated in order to do the money transfers.
According to Alberto Segura and Rolf Govers, malware analysts at cybersecurity firm NCC Group, these features can be used to simulate touches/clicks and button presses. So it can be used not only to automatically transfer money but also install other malicious applications or components.
The latest version spotted on the Google Play Store on February 28 are a number of dropper apps that also leverages Android’s Direct Reply functionality to propagate itself to other devices, making it the second banking trojan after FluBot to intercept notifications for wormable attacks.
The list of malicious apps, all of which were updated on February 10, have been collectively installed about 57,000 times to date –
- Antivirus, Super Cleaner (com.abbondioendrizzi.antivirus.supercleaner) – 1,000+ installs
- Atom Clean-Booster, Antivirus (com.abbondioendrizzi.tools.supercleaner) – 500+ installs
- Alpha Antivirus, Cleaner (com.pagnotto28.sellsourcecode.alpha) – 5,000+ installs, and
- Powerful Cleaner, Antivirus (com.pagnotto28.sellsourcecode.supercleaner) – 50,000+ installs
SharkBot enables the adversary to inject fraudulent overlays atop official banking apps to steal credentials, log keystrokes, and obtain full remote control over the devices, but only after the victims grant it Accessibility Services permissions.
Image Credits : Defpr

















Comments